IP Library › Granted Patent US 12,328,571
Granted Patent B2
US 12,328,571 · App. 17/424,057 · Granted Jun 10, 2025

Securing the user plane path for a group communication session based on a security policy common to all devices in the group

Inventors: Vlasios Tsiatsis (Solna, SE); Noamen Ben Henda (Vällingby, SE); Monica Wifvesson (Lund, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W12/033H04L63/104H04W4/08H04W12/76H04W76/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,328,571
App. No.
17/424,057
Granted
Jun 10, 2025
Kind
B2
Abstract

A network node ( 26, 400 ) is configured for use in a wireless communication network ( 10 ). The network node ( 26, 400 ) receives a request to establish a session ( 14 - 1 ) for a device ( 12 - 1 ) in a group ( 18 ), e.g., a 5G Local Area Network group ( 18 ). The network node ( 26, 400 ) determines a user plane security policy ( 24 - 1 ) for the session (! 4 - 1 ), based on a user plane security policy ( 28 ) for the group ( 18 ). The user plane security policy ( 28 ) for the group ( 18 ) may specify a policy for securing a user plane path of a session for any device in the group ( 18 ). The network node ( 26, 400 ) may then transmit, to an access node of the wireless communication network ( 10 ), control signaling indicating the determined user plane security policy ( 24 - 1 ).

Claims (45)

1. A method performed by a network node which implements a Session Management Function in a 5G core network of a wireless communication network, the method comprising:

receiving, at the network node, a request to establish a session for a device in a 5G Local Area Network (5GLAN) group;

determining a user plane security policy for the session, based on a user plane security policy for the 5GLAN group, wherein the user plane security policy for the 5GLAN group specifies a policy for securing a user plane path of a session for any device in the 5GLAN group; and

transmitting, from the network node to an access node of the wireless communication network, control signaling indicating the determined user plane security policy.

2. The method of claim 1 , wherein, according to the user plane security policy for the 5GLAN group, a user plane security policy for a session of any device in the 5GLAN group is to be the same as a user plane security policy for a session of any other device in the 5GLAN group.

3. The method of claim 1 , wherein said determining comprises determining the user plane security policy for the session to be the same as a user plane security policy for a different session or a different device in the 5GLAN group.

4. The method of claim 1 , wherein, according to the user plane security policy for the 5GLAN group, a user plane security policy for a session of any device in the 5GLAN group is to specify a minimum level of security.

5. The method of claim 1 , wherein the user plane security policy for the 5GLAN group indicates:

whether confidentiality protection is required or not needed for securing a user plane path of a session for any device in the 5GLAN group; and/or

whether integrity protection is required or not needed for securing a user plane path of a session for any device in the 5GLAN group.

6. The method of claim 1 , wherein the user plane security policy for the 5GLAN group indicates:

whether confidentiality protection is required, preferred, or not needed for securing a user plane path of a session for any device in the 5GLAN group;

whether integrity protection is required, preferred, or not needed for securing a user plane path of a session for any device in the 5GLAN group.

7. The method of claim 1 , further comprising obtaining the user plane security policy for the 5GLAN group from a node implementing an application function, a node in a data network, a node in an operations and support system (OSS) a node implementing a unified data management (UDM) function, or a node implementing a policy control function (PCF).

8. The method of claim 1 , further comprising obtaining or generating the user plane security policy for the 5GLAN group during a procedure for establishing the session.

9. The method of claim 1 , wherein the 5GLAN group is a restricted set of devices configured to privately communicate amongst each other via the respective sessions for the devices.

10. The method of claim 1 , wherein the request indicates a data network name (DNN) associated with the 5GLAN group.

11. The method of claim 1 , wherein the 5GLAN group is a restricted set of devices configured to privately communicate amongst each other via a 5GLAN type service.

12. A non-transitory computer readable storage medium comprising a computer program comprising instructions which, when executed by at least one processor of a network node which implements a Session Management Function in a 5G core network of a wireless communication network, causes the network node to:

receive, at the network node, a request to establish a session for a device in a 5G Local Area Network (5GLAN) group;

determine a user plane security policy for the session, based on a user plane security policy for the 5GLAN group, wherein the user plane security policy for the 5GLAN group specifies a policy for securing a user plane path of a session for any device in the 5GLAN group; and

transmit, from the network node to an access node of the wireless communication network, control signaling indicating the determined user plane security policy.

13. A network node configured for use in a wireless communication network, the network node implementing a Session Management Function in a 5G core network of the wireless communication network and comprising:

communication circuitry; and

processing circuitry configured to:

receive, at the network node, a request to establish a session for a device in a 5G Local Area Network (5GLAN) group;

determine a user plane security policy for the session, based on a user plane security policy for the 5GLAN group, wherein the user plane security policy for the 5GLAN group specifies a policy for securing a user plane path of a session for any device in the 5GLAN group; and

transmit, from the network node to an access node of the wireless communication network, control signaling indicating the determined user plane security policy.

14. The network node of claim 13 , wherein, according to the user plane security policy for the 5GLAN group, a user plane security policy for a session of any device in the 5GLAN group is to be the same as a user plane security policy for a session of any other device in the 5GLAN group.

15. The network node of claim 13 , wherein the processing circuitry is configured to determine the user plane security policy for the session to be the same as a user plane security policy for a different session for a different device in the 5GLAN group.

16. The network node of claim 13 , wherein, according to the user plane security policy for the 5GLAN group, a user plane security policy for a session of any device in the 5GLAN group is to specify a minimum level of security.

17. The network node of claim 13 , wherein the user plane security policy for the 5GLAN group indicates:

whether confidentiality protection is required or not needed for securing a user plane path of a session for any device in the 5GLAN group; and/or

whether integrity protection is required or not needed for securing a user plane path of a session for any device in the 5GLAN group.

18. The network node of claim 13 , wherein the user plane security policy for the 5GLAN group indicates:

whether confidentiality protection is required, preferred, or not needed for securing a user plane path of a session for any device in the 5GLAN group;

whether integrity protection is required, preferred, or not needed for securing a user plane path of a session for any device in the 5GLAN group.

19. The network node of claim 13 , wherein the processing circuitry is further configured to obtain the user plane security policy for the 5GLAN group from a node implementing an application function, a node in a data network, a node in an operations and support system (OSS) a node implementing a unified data management (UDM) function, or a node implementing a policy control function (PCF).

20. The network node of claim 13 , wherein the processing circuitry is further configured to obtain or generate the user plane security policy for the 5GLAN group during a procedure for establishing the session.

21. The network node of claim 13 , wherein the 5GLAN group is a restricted set of devices configured to privately communicate amongst each other via the respective sessions for the devices.

22. The network node of claim 13 , wherein the request indicates a data network name (DNN) associated with the 5GLAN group.

23. The network node of claim 13 , wherein the 5GLAN group is a restricted set of devices configured to privately communicate amongst each other via a 5GLAN type service.

24. The method of claim 1 , wherein individual user plane security policies for the respective devices in the 5GLAN group are to specify respective extents to which user plane paths of sessions for devices in the 5GLAN group are to be secured, and wherein the user plane security policy for the 5GLAN group specifies that:

the individual user plane security policies for the respective devices in the 5GLAN group are to be the same; or

for each of the devices in the 5GLAN group, the individual user plane security policy for the device is to specify at least a minimum extent to which the user plane path of the session for the device is to be secured.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2021
From: BEN HENDA, NOAMEN; TSIATSIS, VLASIOS; WIFVESSON, MONICA
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 056903/0475 →
Continuity (2)
Provisional Application 62794906 · Jan 21, 2019
Related Publication 20220124488A1 · Apr 21, 2022
References Cited (19)
US 20130103939A1 · Radpour · 2013 [cited by examiner]
US 20190387401A1 · Liao · 2019 [cited by examiner]
US 20200059761A1 · Li · 2020 [cited by examiner]
US 20210185538A1 · Zhang · 2021 [cited by examiner]
US 20210409941A1 · Rajendran · 2021 [cited by examiner]
CN 107786511A · 2018 [cited by applicant]
EP 3177052A1 · 2017 [cited by applicant]
WO 2018194971A1 · 2018 [cited by applicant]
3GPP, “3GPP TS 23.501 V15.4.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System; Stage 2 (Release 15), Dec. 2018, 1-236. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System; Stage 2 (Release 15)”, TS 23.502 V15.4.1, Jan. 2019, 1-347. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System; Stage 2 (Release 15)”, 3GPP TS 23.502 V15.3.0, Sep. 2018, 1-330. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15)”, 3GPP TS 33.501 V15.3.1, Dec. 2018, 1-181. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15)”, 3GPP TS 33.501 V15.1.0, Jun. 2018, 1-152. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on enhancement of 5GS for Vertical and LAN Services (Release 16)”, TR 23.734 V16.0.0 (Dec. 2018), Dec. 2018, 1-… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System; Stage 2 (Release 15)”, 3GPP TS 23.501 V15.3.0, Sep. 2018, 1-226. [cited by applicant]
Ericsson, “New security solution for handling UP security policy for a 5GLAN Group”, 3GPP TSG SA WG3 (Security) Meeting #94, S3-190290 (revision of S3-19xabc), Kochi, India, Jan. 28-Feb. 1, 2019, 1-2. [cited by applicant]
Huawei, et al., “5GLAN group management procedures”, 3GPP, TSG-SA WG2 Meeting #130, S2-1900674, Kochi, India, Jan. 21-25, 2019, 1-11. [cited by applicant]
Huawei, et al., “Support one to many communication for 5GLAN”, 3GPP TSG-SA WG2 Meeting #130, S2-1900597, Kochi, India, Jan. 21-25, 2019, 1-11. [cited by applicant]
3GPP, “3GPP TS 33.819 V0.2.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security for 5GS enhanced support of Vertical and LAN Services; (Release 16), Dec. 2… [cited by applicant]